Register4Less.com Account Security Features
December 14th, 2015Domain security is in our opinion the most important service a registrar can provide for their clients. The ramifications of an account being compromised are potentially huge.
Encrypted Passwords
Your password, whether it’s for domain management, and FTP password, or access to your email are stored encrypted. We do keep the last 4 characters of the login password for account verification purposes. Keeping passwords encrypted in our databases ensure only you (and those to whom you have chosen to share your password) will be able to log into your account with us. No employee or service provider to register4less.com will ever be able to see your login password.
Login Security Agent
Our patented Login Security Agent provides 24/7 account monitoring, and is set up to notify you when a login session has been created on your account. In addition to notifying you of a successful login to your account, the LSA service gives you the ability to terminate the login session.
LSA has been designed to deal with the one element of account security that we as a registrar cannot control, the human factor. Ways in which an account could be compromised include:
- Leaving a login session active on computer
- Logging into your account on a public terminal that’s infected with malware
- Sending an email in plaint text with the account information in the body of the email
- Leaving login credentials written down, etc.
When you set up LSA on your account, you will specify LSA to send a notification when logging in from a connection on any IP address, or you can specify an IP to be ignored. You will create a “kill password” with the account as well. This kill password cannot be changed, so you want to ensure it’s one that you will remember.
Let’s go with the scenario that someone malicious has gained your login username and password, and is logging into your account in order to steal your domains. As soon as this person logs into your account, you will receive a notice that a login session has been created, and from what IP address the person is connecting. You will recognize that this is not you logging in.
To kick the hacker off, log into your account, and go to Profile > Login Security Agent. You’ll enter in the Kill Password, and then click the Kill Sessions button. The next link the hacker will click will log them off the account. The login password is automatically reset by LSA when you click the Kill Sessions button. You’ll then need to change your password to a new one, and your account is now once again secure.
Two Factor Authentication
Two Factor Authentication combines the Google Authenticator app for your smartphone and your normal login password password. The app will generate a 6 digit number that’s unique to the app that’s running on your phone. When you log in, you will enter in the 6 digit code after your password (no spaces).